At the time of writing, only 5 of the 43 AV engines at Virus Total did detect the trojan. The trojan is known as Gen:Trojan.Heur.FU.cC0@a4DqMHii (BitDefender), W32/Trojan3.BZM (F-Prot) or W32/Obfuscated.BQ!genr (Norman).

I have seen this Trojan but in a slightly different format. The jpg didn’t come as an attachment. The attachments received were eFAX???DOC.zip file containing a eFAX_?????DOC.exe executable

The registry entries mentioned above weren’t created/affected but there were a number of files in the temp directory such as m.21ac.tmp.exe. These could have been created by a different Trojan but were only notices after a user opened and run th attachment in the mail. Comodo detected these files in the temporary directory but didn’t detect any Trojans. MalwareBytes detected the Trojan (can’t remember which ones) and has so far seemed to remove them